Vulnerability record · CVE-2021-25282 · published 27 February 2021
CVE-2021-25282: SaltStack Salt wheel pillar_roots.write directory traversal
Saltstack · Salt
SaltStack Salt before 3002.5 exposes a directory traversal flaw in the salt.wheel.pillar_roots.write method. An unauthenticated remote attacker can abuse path handling to write files outside the intended pillar roots directory. Because Salt is a configuration management and remote execution platform, arbitrary file write on the master can lead to remote command execution and full control of managed infrastructure.
Description
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 with unauthenticated network reachability, public exploit code and an EPSS above 0.92 make this an urgent patch target despite no KEV listing.
What it is
SaltStack Salt before 3002.5 exposes a directory traversal flaw in the salt.wheel.pillar_roots.write method. An unauthenticated remote attacker can abuse path handling to write files outside the intended pillar roots directory. Because Salt is a configuration management and remote execution platform, arbitrary file write on the master can lead to remote command execution and full control of managed infrastructure.
Impact
An attacker gains the ability to write arbitrary files on the Salt master, which can be leveraged to execute commands and take over the master and its managed minions. Integrity and availability are both rated high in the CVSS vector, with no confidentiality impact stated.
Attack surface
The flaw is reachable over the network through the Salt API/wheel interface, with the CVSS vector indicating no authentication (PR:N) and no user interaction (UI:N). Any exposed Salt API endpoint is a potential entry point.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.924 (99.8th percentile) and a public exploit reference exists (Packet Storm, tagged Exploit), indicating mature, widely available exploitation.
What to do
- Upgrade Salt to 3002.5 or later immediately; this is the vendor-fixed release.
- Apply distribution updates for Debian, Fedora and Gentoo packages that backport the fix.
- Restrict network access to the Salt API and wheel interfaces to trusted management networks only.
- Run the Salt master with least privilege and isolate it from unrelated systems to limit file-write impact.
- Audit pillar root directories for unexpected or modified files.
Detection
- Monitor Salt master logs for wheel pillar_roots.write calls, especially with traversal sequences such as ../ in paths.
- Alert on file creation or modification outside configured pillar roots on the Salt master.
- Detect unexpected child processes or command execution spawned by the salt-master service.
- Review network logs for external connections to the Salt API port from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-25282 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25282), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.